Executive brief
Ninja Forms - File Uploads is a WordPress plugin used to handle file submissions through web forms. A security flaw in this plugin allows unauthorized individuals to access or delete internal debug logs. While this does not directly expose customer form submissions, it allows attackers to tamper with system logs, potentially hindering troubleshooting or hiding other malicious activities.
Technical details
The Ninja Forms - File Uploads plugin for WordPress (versions up to 3.3.29) contains a missing authorization vulnerability (CWE-862) within its debug logging functionality. The issue resides in the `DebugLog.php` component, where the plugin fails to verify user permissions before executing actions on the `wp_nf3_log` database table. An unauthenticated remote attacker can exploit this to read all debug log entries or permanently delete the entire log table. The attack is carried out via network requests to the affected routes without requiring any prior authentication or user interaction.
Affected products
- SaturdayDrive Ninja Forms - File Uploads up to, and including, 3.3.29
Timeline
- 2026-07-03: disclosed: Initial publication of the CVE record
- 2026-07-03: advisory: Wordfence published vulnerability details